Vulnerabilidades em HCL Software

384 resultados
Análise Vexday

Com 334 CVEs catalogadas e nenhuma registrada no catálogo de exploração ativa da CISA (KEV), o perfil de risco imediato da HCL Software situa-se abaixo da média geral do catálogo, o que sugere pressão operacional menor em termos de resposta emergencial. No entanto, a presença de 10 vulnerabilidades de severidade crítica exige atenção contínua, ainda que nenhuma delas possua prova de conceito pública conhecida no momento. A CVE mais perigosa atualmente apontada é a CVE-2023-37536, com escore EPSS de 0,0138, indicando probabilidade de exploração relativamente baixa, mas não desprezível dentro do horizonte de monitoramento. O tipo de falha mais recorrente — CWE-79 (Cross-Site Scripting) — e o surgimento de 8 novas CVEs nos últimos 90 dias reforçam a necessidade de ciclos regulares de revisão, especialmente em componentes voltados à interface web.

CVE-2026-35142LOWHCL DFXAnalytics is affected by an Internal IP Address Disclosure vulnerability.EPSS 0.3%CVE-2023-50346LOWAn information disclosure affects DRYiCE MyXalyticsEPSS 0.3%CVE-2023-45700MEDIUMHCL Launch is susceptible to an HTML injection vulnerabilityEPSS 0.3%CVE-2023-28025MEDIUMAn HTML injection vulnerability can affect HCL BigFix Mobile / Modern Client Management EPSS 0.3%CVE-2022-38658HIGHHCL BigFix Server Automation (SA) is affected by a security vulnerability around Notification Service EPSS 0.3%CVE-2024-30132LOWMissing default HTTP security headers affect HCL Nomad server on DominoEPSS 0.3%CVE-2024-30118LOWHCL Connections is susceptible to a sensitive information disclosure vulnerabilityEPSS 0.3%CVE-2024-30129MEDIUMHCL Nomad server on Domino is affected by a host header injection vulnerabilityEPSS 0.3%CVE-2023-45720MEDIUMHCL Leap is affected by a disclosure of private personal information vulnerabilityEPSS 0.3%CVE-2024-23559MEDIUMHCL DevOps Deploy / Launch is generating an obsolete HTTP header EPSS 0.3%CVE-2024-23558MEDIUMHCL DevOps Deploy / HCL Launch does not invalidate all session authentication cookies after logoutEPSS 0.3%CVE-2023-37539HIGHHCL Domino Catalog template is susceptible to a Stored Cross-Site Scripting (XSS) vulnerabilityEPSS 0.3%CVE-2023-28016LOWHCL BigFix OSD Bare Metal Server is affected by a host header injection vulnerabilityEPSS 0.3%CVE-2025-0277MEDIUMHCL BigFix Mobile is affected by an insecure Content Security Policy (CSP)EPSS 0.3%CVE-2025-0276MEDIUMHCL BigFix Modern Client Management (MCM) is affected by an insecure Content Security Policy (CSP)EPSS 0.3%CVE-2024-30113MEDIUMHCL Leap is affected by a cross-site scripting (XSS) vulnerabilityEPSS 0.3%CVE-2025-0257MEDIUMHCL DevOps Deploy / HCL Launch is susceptible to unauthorized access to other servicesEPSS 0.3%CVE-2023-28021MEDIUMBigFix WebUI is vulnerable to use of a risky cryptographic algorithm EPSS 0.3%CVE-2022-38660HIGHHCL XPages applications are susceptible to Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.3%CVE-2026-35148MEDIUMHCL DFXServer is affected by a Missing Access Control vulnerabilityEPSS 0.3%